CVE-2017-11352

Description

In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.979

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.5Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.5Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.5Windows
Image manipulation programs and library (USN-3302-1) libmagick++-6.q16-7_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3302-1) libmagick++-6.q16-7_6.9.7.4+dfsg-3ubuntu1.2_amd64.debLinux
Image manipulation programs and library (USN-3302-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3302-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-3ubuntu1.2_amd64.debLinux
Imagemagick 6.9.7.4 dfsg-3ubuntu1.1 for Ubuntu 17.04 (x64) imagemagick_6.9.7.4+dfsg-3ubuntu1.2_amd64.debLinux
Imagemagick 6.9.7.4 dfsg-3ubuntu1.1 for Ubuntu 17.04 imagemagick_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3363-1) imagemagick_6.7.7.10-6ubuntu3.8_i386.debLinux
Image manipulation programs and library (USN-3363-1) imagemagick_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3363-2) imagemagick_6.8.9.9-7ubuntu5.11_amd64.debLinux
Image manipulation programs and library (USN-3363-2) imagemagick_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3363-2) libmagick++5_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3222-1) imagemagick_6.8.9.9-7ubuntu5.11_amd64.debLinux
Image manipulation programs and library (USN-3222-1) imagemagick_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3222-1) libmagick++5_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.8.9.9-7ubuntu5.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.7.7.10-6ubuntu3.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu2.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu2.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu6.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu6.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++5_6.7.7.10-6ubuntu3.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore5_6.7.7.10-6ubuntu3.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore5_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu2.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu2.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu6.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu6.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu2.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu2.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu6.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu6.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.11_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234